- The same auditor license number (PAC-FIRM-LIC-47383) appears in 487 out of 494 reports
- Every Type II report has identical page numbers: Section 4 at page 30, tests at page 59, Section 5 at page 82
- 220+ "No exceptions noted" per report, across every single client
- The system descriptions were copy-pasted from each company's marketing website
We built tools to check this data:
- Search by company name to see if they're in the leaked database
- Paste any SOC 2 report text to scan for 10 template fingerprints
- A swipe game where you try to tell real audit excerpts from the fakes (harder than you'd think)
455 companies indexed, all free, no signup needed.
I'm also curious what the HN community thinks about the fingerprint detection approach, are there patterns we're missing?